Tech Stack
AWSCloudPythonTerraform
About the role
- Design, develop, and deploy custom and AWS-native security policies (e.g., SCPs, IAM policies, AWS Config Rules) across AWS accounts.
- Perform pre-deployment compliance assessments and identify non-compliant configurations in AWS environments.
- Collaborate with application and infrastructure teams to remediate misconfigurations and implement secure-by-design practices.
- Validate and monitor policy effectiveness post-deployment using tools like AWS Config, Security Hub, CloudTrail, and GuardDuty.
- Own and manage the AWS policy exemption workflow — review exception requests, conduct risk assessments, and track approvals.
- Maintain detailed documentation on policy changes, enforcement status, and exception decisions.
- Participate in tool evaluations and implementations that support cloud security posture management and automation.
- Support continuous improvement of cloud security posture through quarterly reviews, metrics, and tuning recommendations.
Requirements
- Minimum 3 years of hands-on experience in AWS cloud security or policy enforcement.
- Strong working knowledge of AWS security services: IAM, SCPs, AWS Config, Security Hub, CloudTrail, GuardDuty, KMS, etc.
- Experience with cloud compliance standards (e.g., CIS AWS Foundations Benchmark, NIST, ISO 27001, HIPAA).
- Proficient in writing and troubleshooting IAM policies, JSON/YAML templates, Lambda functions, and scripting (Python/Bash).
- Familiarity with DevSecOps practices and Infrastructure as Code (IaC) tools such as Terraform or CloudFormation.
- Preferred Certifications: AWS Certified Security – Specialty; AWS Certified Solutions Architect – Associate or Professional.
- Excellent communication and stakeholder collaboration skills.
- Strong analytical thinking and problem-solving abilities.
- Ability to manage multiple tasks and priorities in a fast-paced environment.
ATS Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
AWS cloud securitypolicy enforcementIAM policiesJSONYAMLLambda functionsPythonBashTerraformCloudFormation
Soft skills
communicationstakeholder collaborationanalytical thinkingproblem-solvingtask managementprioritization
Certifications
AWS Certified Security – SpecialtyAWS Certified Solutions Architect – AssociateAWS Certified Solutions Architect – Professional